Chapter 3 of 10
Assessing Likelihood, Impact, and Exposure
Not all risks deserve the same attention; this module walks through practical ways to judge which threats are most likely to hurt your supply chain and by how much.
1. From Risk List to Risk Priorities
From List to Priorities
You already mapped where things can go wrong. The next challenge is deciding which risks deserve attention first so limited time and budget go to the most important threats.
Three Core Ideas
We focus on three ideas: likelihood (how probable a risk is), impact (how bad it is if it happens), and exposure (how much of your operations or revenue is affected).
Why This Matters in 2026
More frequent disruptions, stricter regulations, and board-level pressure mean companies must show a structured approach to risk, not just react when things break.
Your Learning Goals
You will learn to distinguish likelihood, impact, and exposure; build and read a simple risk matrix; and compare qualitative scoring with quantitative metrics like expected loss.
2. Clarifying Likelihood, Impact, and Exposure
What Is Likelihood?
Likelihood is the probability a specific risk event occurs in a given time window, often described as Rare, Possible, or Likely, or as a percentage such as 20% per year.
What Is Impact?
Impact is how severe the consequences are if the event occurs. In supply chains this includes money lost, downtime, delivery delays, and compliance or reputation damage.
What Is Exposure?
Exposure is how much of your organization is affected: share of revenue tied to a supplier, number of sites relying on a hub, or percent of volume through one port.
How They Work Together
Likelihood and impact form the classic risk matrix. Exposure refines impact by showing how concentrated or systemic the damage would be across your network.
3. Concrete Supply Chain Scenarios
Scenario A: Port Congestion
60% of your imported components pass through one Asian port. Likelihood is high, impact is weeks of delay and extra cost, and exposure is very high because most inbound volume depends on it.
Scenario B: Cyberattack on WMS
Your main DC uses a single cloud WMS. Likelihood is moderate, impact is 2–3 days of disruption and penalties, and exposure is high for that DC but not for other regions.
Scenario C: Supplier Strike
A smaller supplier of non-critical packaging may face a strike. Likelihood is moderate, impact is small with alternatives available, and exposure is low to a small product line.
Comparing the Three
Port congestion is high likelihood, high impact, high exposure; cyberattack is moderate likelihood, high impact; supplier strike is moderate likelihood, low impact. Port congestion clearly ranks higher.
4. Building a Simple Risk Matrix (Heat Map)
What Is a Risk Matrix?
A risk matrix or heat map combines likelihood and impact on a grid so you can see which risks are both probable and severe at a glance.
Step 1: Choose Scales
Use 1–5 scales for likelihood and impact. For example, likelihood from 1 Rare to 5 Almost Certain, and impact from 1 Insignificant to 5 Severe.
Step 2: Define Criteria
Reduce subjectivity by linking scores to thresholds, such as dollar loss ranges or hours of downtime for each impact level from 1 to 5.
Step 3: Plot and Interpret
Plot risks with likelihood on the X-axis and impact on the Y-axis. Top-right cells (high–high) are priority. Size or labels can show exposure, such as percent of revenue affected.
5. Place Risks on a Matrix (Thought Exercise)
Use the three scenarios from Step 3 and mentally place them on a 1–5 likelihood and 1–5 impact matrix.
Assume:
- Likelihood scale: 1 Rare, 2 Unlikely, 3 Possible, 4 Likely, 5 Almost Certain
- Impact scale (financial + operational combined): 1 Insignificant, 2 Minor, 3 Moderate, 4 Major, 5 Severe
Task:
- For each scenario, assign a likelihood score (1–5) and an impact score (1–5).
- Then rank the three risks from highest to lowest priority.
Scenarios (reminder):
- A: Port congestion at major Asian hub
- B: Cyberattack on main WMS
- C: Strike at secondary supplier
Write down your answers before viewing the suggested solution below.
Suggested answers (one reasonable approach):
- A: Likelihood 4 (Likely), Impact 4 (Major)
- B: Likelihood 3 (Possible), Impact 4 (Major)
- C: Likelihood 3 (Possible), Impact 2 (Minor)
Ranking:
- A (4,4) – high likelihood and major impact
- B (3,4) – slightly less likely but still major impact
- C (3,2) – similar likelihood but much lower impact
Reflection questions:
- Would your scores change if the port handled only 20% of your volume instead of 60%? How does that relate to exposure?
- How might regulation or customer expectations change your impact scores (for example, for a cyberattack)?
6. Qualitative vs Quantitative Assessment
Qualitative Assessment
Qualitative assessment uses categories like High/Medium/Low or 1–5 scores without exact numbers. It is easy to start and works with limited data, but it is subjective.
Quantitative Assessment
Quantitative assessment uses numbers: probabilities, hours of downtime, or dollar losses. It enables cost–benefit analysis but needs data and can give a false sense of precision.
Semi-Quantitative in Practice
Many firms use semi-quantitative scales, where scores map to ranges, such as impact 4 meaning $500k–$2m loss. This balances practicality with analytical rigor.
What You Will Use
In this module you will combine qualitative 1–5 scoring with simple quantitative metrics like expected loss or expected downtime for selected critical supply chain risks.
7. Calculating Expected Loss and Downtime
A basic quantitative idea you should know is expected value.
- Expected loss = probability of the event × loss if it occurs.
- Expected downtime = probability of the event × downtime if it occurs.
This does not capture everything (for example, tail risks, cascading failures), but it is a useful starting point.
Example assumptions:
- Port congestion (Scenario A):
- Probability per year = 0.4 (40%)
- Loss if it occurs = $1,000,000
- Cyberattack (Scenario B):
- Probability per year = 0.2 (20%)
- Loss if it occurs = $1,500,000
Below is a short Python example to compute expected loss and expected downtime for a few risks. You do not need to run it, but reading it will help you see how the logic works.
8. Quick Check: Expected Loss
Use the idea of expected loss to answer this question.
A supplier disruption has:
- 10% chance per year (0.10)
- $2,000,000 loss if it occurs
What is the expected loss per year?
A supplier disruption has a 10% chance per year and would cost $2,000,000 if it occurs. What is the expected loss per year?
- $20,000
- $200,000
- $2,000,000
- $10,000,000
Show Answer
Answer: B) $200,000
Expected loss = probability × loss = 0.10 × $2,000,000 = $200,000 per year. This is the average loss if you could repeat many years under the same conditions.
9. Integrating Exposure into Your Prioritization
Exposure helps you distinguish between two risks that have similar likelihood and impact per event but affect very different parts of your business.
Activity:
- Consider two risks:
- Risk X: Factory fire at Plant A, which makes 80% of your main product line.
- Risk Y: Factory fire at Plant B, which makes 5% of a niche product line.
- Assume:
- Probability of fire at each plant: 1% per year.
- Financial loss if each plant burns down: $10,000,000.
- On a simple likelihood–impact matrix, X and Y look identical:
- Same probability
- Same loss per event
- Now think about exposure:
- Plant A disruption affects 80% of your main revenue stream.
- Plant B disruption affects only 5% of a niche line.
Questions to reflect on:
- Which risk would you prioritize for mitigation and why?
- How could you represent this difference on your heat map without changing the likelihood or impact scores?
Possible answers:
- Most companies would prioritize Risk X because the exposure of key products and customers is much higher.
- On a heat map, you might:
- Use a larger symbol for Risk X
- Add text like "affects 80% of main product revenue" under Risk X
- Tag it as "systemic" vs. "localized" risk.
This illustrates why modern supply chain risk management (as practiced in 2026) increasingly treats exposure and concentration risk as central, not optional.
10. Key Term Review
Flip the cards to review core concepts from this module.
- Risk likelihood
- The probability that a specific risk event occurs in a given time window (for example, per year), often expressed as categories like Rare to Almost Certain or as a percentage.
- Risk impact
- The severity of consequences if a risk event occurs, typically measured in financial loss, operational downtime, customer service impact, and compliance or reputational damage.
- Risk exposure
- The extent of the organization affected by a risk, such as the share of revenue, number of sites, or percentage of volume dependent on a vulnerable supplier, facility, or route.
- Risk matrix (heat map)
- A visual tool that plots risks on a grid of likelihood versus impact, often color-coded, to highlight which risks are low, medium, or high priority.
- Qualitative risk assessment
- An approach that uses descriptive categories or scores (for example, 1–5, High/Medium/Low) without precise numerical probabilities or loss amounts.
- Quantitative risk assessment
- An approach that estimates numerical probabilities, losses, and downtime, enabling calculations such as expected loss and cost–benefit analysis of mitigation options.
- Expected loss
- A basic quantitative metric calculated as probability of an event multiplied by the loss if it occurs, representing the long-run average loss per time period.
Key Terms
- Risk impact
- The magnitude of negative consequences if a risk event occurs, typically including financial, operational, customer, and compliance or reputational effects.
- Expected loss
- The product of the probability of a risk event and the loss if it occurs, representing the average loss per period over many repetitions under similar conditions.
- Risk exposure
- The portion of an organization’s operations, revenue, assets, or partners that would be affected by a given risk, reflecting concentration and systemic vulnerability.
- Risk likelihood
- The probability that a specific risk event occurs within a defined time period, such as a year, sometimes expressed as a qualitative level (for example, Likely) or a numerical probability.
- Concentration risk
- The risk that a large share of business depends on a small number of suppliers, sites, or routes, increasing vulnerability to localized disruptions.
- Risk matrix (heat map)
- A two-dimensional grid that maps risks according to their likelihood and impact, often with color coding to show relative priority levels.
- Qualitative risk assessment
- A method that evaluates risks using descriptive categories or ordinal scales instead of precise numerical estimates.
- Quantitative risk assessment
- A method that evaluates risks using numerical estimates of probability, loss, and other metrics, supporting calculations like expected loss.